TEARDOWN Published 18 September 2026 at 03:46. Evidence-based. Source-cited. No sponsored content.

The Treasury's guide to catching a Post Office style risk before it becomes a scandal just lost four of its practical guides. The link put in their place will not open without a civil service login.

3 out of 5 stars3/54 documented mistakes in this teardownHow ratings work

Estimated reading time: 6 minutes

HM Treasury's building at 1 Horse Guards Road, Westminster, seen from the street.
HM Treasury, 1 Horse Guards Road, Westminster, November 2016. Photo: Dun.can / Wikimedia Commons, CC BY 2.0.

In short. The Orange Book is HM Treasury's central doctrine on how government should identify, escalate and manage risk. On 29 July 2026 its GOV.UK page deleted four of the practical documents that supported it, including the only public guidance on setting risk appetite, saying they no longer reflected current practice. In their place: a line pointing readers to an internal Government Finance Function site, which returns a members-only sign-in page when fetched directly, not the public guidance the Orange Book's own scope says should reach every arm's length body and, where useful, the wider UK public sector. The core Orange Book text has not been substantively revised since May 2023. The same month the guidance was deleted, the Post Office Horizon Inquiry's chair confirmed that the volumes of his final report examining exactly why risk escalation failed at that scale remain unpublished, with no fixed date. Four documented mistakes: three stars.

On 29 July 2026, the GOV.UK page for the Orange Book, HM Treasury's guidance on managing risk across government, quietly got shorter. Its own change log records what happened: four attached documents, Portfolio Risk Management Guidance, the Risk Appetite Guidance Note, the Risk Management Skills and Capabilities Framework and the Good Practice Guide: Risk Reporting, "were deleted as they were out of date, contained links to superseded guidance and no longer fully reflect the current Risk Centre of Excellence thinking and practice" [1]. In their place, the entry adds, "a small line was added to the top of the page including a link to the internal intranet for the Government Finance Function, OneFinance" [1].

The Orange Book itself is not a niche document. Its own scope statement says it "is applicable to all government departments and arm's length public bodies... with responsibility derived from central government for public funds" and "may be useful to all parts of the UK public sector" [2] (page 4). Its Main Principle C states plainly that "risk management shall be collaborative and informed by the best available information and expertise," with Supporting Principle C1 spelling out that this "requires collaboration and cross-organisational working through a range of public sector, private sector and third-sector partnerships" [2] (page 17). Under the document's own "comply or explain" model, that main principle is mandatory: boards "shall consider adherence" to it. Supporting principles like C1, the practical detail of how escalation actually works, are advisory, "should" rather than "shall" [2] (page 5). The four deleted documents were the advisory detail. What replaced them is a link.

What the link actually opens

The Orange Book's own page text, current as of this cycle, describes the replacement directly: "The Risk Management pages of OneFinance contain further guidance on how the Orange Book should be interpreted in practice... These resources are available to most public sector employees at the Risk Centre of Excellence" [1], linking to gff.civilservice.gov.uk. Fetching that URL directly returns a page headed "Government Finance Function OneFinance," describing itself as responsible for "supporting the management of over £800 billion of public expenditure each year, as well as over £2,000 billion in assets and £4,500 billion of liabilities," followed by a "Sign-in Member Login" form asking for an email and password, with a "Need to register?" link beneath it [3]. There is no version of the practical risk guidance visible to a reader who does not sign in.

The Orange Book's own wording, "most public sector employees," is itself an admission that some are excluded, and a login gate to a Government Finance Function site is likely to exclude more than "most" would suggest: local government, NHS bodies and devolved administrations sit outside the civil service network that OneFinance serves, even though the Orange Book's own scope statement says they may find the document "useful" [2] (page 4). The private and third-sector partners that Supporting Principle C1 explicitly names as part of the "extended enterprise" of risk management [2] (page 17) have no plausible route to a civil service login at all. Neither does the public whose money the framework exists to protect.

The claims, tested

The document's own words What the record actually shows Verdict
The Orange Book "is applicable to all government departments and arm's length public bodies... may be useful to all parts of the UK public sector" [2] (page 4) The practical guidance that supports it now sits behind a Government Finance Function login described on the Orange Book's own page as available to "most public sector employees" [1], verified by direct fetch to return a members-only sign-in screen [3] The stated audience is broader than the actual access
The four deleted documents were removed because they "no longer fully reflect the current Risk Centre of Excellence thinking and practice" [1] No public replacement text exists; the GOV.UK page offers a login-gated link in place of the documents themselves, not an updated version of them The stated reason is currency, not redundancy, yet nothing current is published to replace what was current
Supporting Principle C1 requires escalation "through a range of public sector, private sector and third-sector partnerships" [2] (page 17) The only detailed practical guidance on how to do that now requires a civilservice.gov.uk login that private and third-sector partners cannot obtain The partnerships named in the principle are the ones least able to reach the guidance behind it

The mistakes, counted

Four practical guides were deleted for being out of date, with nothing current published to replace them (1). The changelog gives a reason, not a remedy: the documents "no longer fully reflect the current... thinking and practice" [1], but no revised version of the Risk Appetite Guidance Note, the Portfolio Risk Management Guidance, the Skills and Capabilities Framework or the Good Practice Guide: Risk Reporting has been published in their place.

The stated replacement is not publicly accessible (2). The line added to the page points to gff.civilservice.gov.uk, described as available to "most public sector employees" [1]. Fetched directly, that page presents a "Sign-in Member Login" form, not the guidance itself [3].

The core document has not been substantively revised since May 2023 (3). The attached PDF is still titled HMT_Orange_Book_May_2023.pdf [2], meaning the government's central risk-management principles have not been updated across the entire period in which the Post Office Horizon Inquiry has been taking evidence on the country's largest known failure of exactly that discipline.

Access is narrower than the document's own stated scope (4). The Orange Book applies formally to "all government departments and arm's length public bodies" and says it "may be useful to all parts of the UK public sector" [2] (page 4). A civil service intranet login reaches neither the wider public sector the document names as a potential user nor the private and third-sector partners Principle C1 names as part of the risk-management "extended enterprise" [2] (page 17).

Why the timing matters

The deletion landed in the same month that the Post Office Horizon Inquiry's chair, Sir Wyn Williams, published a progress update on the parts of his final report that have not yet appeared. Volume 1, covering the human impact of the scandal and redress, was published on 8 July 2025 [4]. His update from 8 July 2026, a year on, confirms that the remaining five volumes, covering the period from "the birth of Legacy Horizon" onwards and, by extension, the governance and risk-escalation failures that let wrongful convictions accumulate for years, are still being written. His original plan to complete them within about twelve months "was too optimistic," he writes, and the volumes are now going through Maxwellisation, the legal process of warning individuals and institutions who may be criticised before publication, with no date given for when it will finish [5].

The scale of what is being assessed is not in doubt. As of 31 July 2026, approximately £1,666 million has been paid to more than 13,300 claimants across the Horizon compensation schemes [6]. The Orange Book's own text never mentions the Post Office or Horizon by name; the only "horizon" it discusses is horizon scanning, a coincidence of terminology, not a reference to the scandal. Whatever lessons the Inquiry's still-unpublished volumes eventually draw about how risk signals get lost inside a large public body, they will land on a framework whose own practical guidance has just been made harder to read, not easier.

Credit where due

The government has not hidden the scale of Horizon redress: the monthly data behind the £1,666 million figure is published in detail, broken down by scheme, updated as recently as 31 July 2026 [6], and the Orange Book page's other attachment, the Central Government's Assurance Directory, was refreshed for Spring 2026 [1], so the page has not been left to rot altogether. Maxwellisation is a genuine legal safeguard, not an excuse: individuals and institutions facing criticism in a public report are entitled to notice and a chance to respond, and Sir Wyn Williams has been transparent about the delay through a public statement rather than silence [5], naming his original timetable as wrong rather than letting the date quietly slip unremarked.

Verdict

Three stars, from four documented mistakes. The Orange Book still states the right principle: risk management should be collaborative, escalated and informed by the best available evidence, across public, private and third-sector partners alike. What it no longer does is make the practical guidance behind that principle available to the partners it names. Four documents were deleted this summer for being out of date, and nothing current replaced them in public. The link left behind opens only for people who can already sign in. And the framework itself has sat unrevised since May 2023, waiting on an account of what went wrong at the Post Office that its own author says is taking longer than he expected to write.

Sources

  1. The Orange Book, HM Treasury, last updated 29 July 2026
  2. The Orange Book: Management of Risk, Principles and Concepts (PDF, May 2023), HM Treasury
  3. Risk Management Centre of Excellence, Government Finance Function (OneFinance)
  4. Reports and statements, Post Office Horizon IT Inquiry
  5. Progress Update from Sir Wyn Williams, Post Office Horizon IT Inquiry, 8 July 2026
  6. Post Office Horizon financial redress data as of 31 July 2026, GOV.UK
SHARE THIS ARTICLEXBlueskyMastodonLinkedInRedditEmail